Wonder if there's conflicts between SE and Vasco's software somewhere
Wonder if there's conflicts between SE and Vasco's software somewhere
Perhaps the "certain condition" was "because your account was hacked because there are dozens if not hundreds of working 6-digit codes for your account at any given time".
Originally Posted by Corrderio View Post
SE just had a PlayOnline version update. Maybe that fixed it?Guess not.[Update Details]
- An issue has been addressed where players would be unable to place a GM petition through the PlayOnline Viewer under a certain condition
I am thinking it is necessary for a bunch of codes to work at the same time because of clock differences. If these things are supposed to last 5+ years, how long can a shitty quartz clock stay accurate to the minute, which is what would be required if you only had 1-2 working codes at a time.
Yep.. I'm glad I waited on purchasing this thing now. Would it be too optimistic to hope that SE fixes this shit within six months?
There's really nothing wrong with them.
Wait a second, we are inputting our new SE acct and password into POL correct?
If the account thieves were able to get our POL ID and PW before, can't they just grab POL ID / PW and SE Username / PW and detach our token? Does the detach method have any protection as to who can detach, like to detach please provide the current password on the token?
my arguement was they could login to ur SE account and just detach your token (i did not know the process), but it was said you need to provide the token generated pw and the serial to detach.
even so it seems right now everyone is still vulnerable for 25 minutes after the PW is generated / typed. if they wanted accounts with tokens, they just need to work realtime, and as POL ID / PW + SE User / PW + Tokens come in, they have 25 minutes until the token expires, its broken the token NEEDS to expire as soon as its used once
It does. And all passwords previous to that password.
But that's irrelevant really because if you haven't logged in in the last 26-30 mins then there are 40ish working codes that someone can use to login. But this seems acceptable to me, seeing as how clocks aren't going to be perfectly synchronized, and this cost $10.
Yea, but the token password is not expiring when its used, leaving a window of 25 minutes for your SE OR POL account to be accessed by anyone. I know all these viruses providing account info will need to be redone to provide a couple more fields from the login form, but it is definately a possiblity down the road if it doesnt get fixed.
shaddix, didn't you post that the old password worked for 26 minutes after you used it to login?
Maybe I worded it badly, if you press the button to get a code, that code works for 26 mins. After that it goes bad.
If you press the button to get a code, wait 5 minutes, press the button to get another code. Login with the 2nd code, the old code will not work, and neither will the one you just used, anymore.
I guess i misunderstood, I was under the impression that a USED token code was working for up to 26 minutes AFTER a login. Sorry
Just a time difference is what I mean. Token is hashing a new code every 40 seconds or so.
So it's like:
0:00 = 1234
0:40 = 5678
1:20 = 8901
If you use the code that was hashed at 1:20to login, the 1234 and 5678 codes become disabled, as does the 8901.
OH I see, so once you use it, it expires but if you just push the button the code is good for 26 min? Makes sense now, I think I need more coffee.
So theres really no problem, and this gives someone 26 minutes to have their overseas loved ones to call them with the code. =)